This update for dovecot24 fixes the following issues:
- Update dovecot to 2.4.2:
- CVE-2025-30189: Fixed users cached with same cache key when
auth cache was enabled (bsc#1252839)
- Changes
- auth: Remove proxy_always field.
- config: Change settings history parsing to use python3.
- doveadm: Print table formatter - Print empty values as "-".
- imapc: Propagate remote error codes properly.
- lda: Default mail_home=$HOME environment if not using userdb
lookup
- lib-dcrypt: Salt for new version 2 keys has been increased to
16 bytes.
- lib-dregex: Add libpcre2 based regular expression support to
Dovecot, if the library is missing, disable all regular
expressions. This adds libpcre2-32 as build dependency.
- lib-oauth2: jwt - Allow nbf and iat to point 1 second into
future.
- lib: Replace libicu with our own unicode library. Removes
libicu as build dependency.
- login-common: If proxying fails due to...
Read the Full Advisory- openSUSE Leap 16.0:
dovecot24-2.4.2-160000.1.1
dovecot24-backend-mysql-2.4.2-160000.1.1
dovecot24-backend-pgsql-2.4.2-160000.1.1
dovecot24-backend-sqlite-2.4.2-160000.1.1
dovecot24-devel-2.4.2-160000.1.1
dovecot24-fts-2.4.2-160000.1.1
dovecot24-fts-flatcurve-2.4.2-160000.1.1
dovecot24-fts-solr-2.4.2-160000.1.1
* bsc#1252839
References:
* https://www.suse.com/security/cve/CVE-2025-30189.html
Get the latest Linux and open source security news straight to your inbox.